CVE-2020-14369

This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a web application in which the user is currently authenticated. An attacker can make a forgery HTTP request to the server by crafting custom flash file which can force the user to perform state changing requests like provisioning VMs, running ansible playbooks and so forth.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1871921 Issue Tracking Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:cloudforms:*:*:*:*:*:*:*:*

Information

Published : 2020-12-02 07:15

Updated : 2020-12-04 13:12


NVD link : CVE-2020-14369

Mitre link : CVE-2020-14369


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

redhat

  • cloudforms